Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
One interesting feature of Persirai is that when it compromises an IP camera, that camera will start attacking others by exploiting three known vulnerabilities: ... CVE-2014-8361 – this vulnerability allows remote attackers to execute arbitrary code via a crafted New Internal Client request. | Early last month we discussed a new Internet of Things (IoT) botnet called Persirai ... which targets over 1000 Internet Protocol (IP) camera models.
After receiving commands from the server, the IP Camera will then start automatically attacking other IP Cameras by exploiting a zero-day vulnerability that was made public a few months ago. Attackers exploiting this vulnerability will be able to get the password file from the user, providing them the means to do command injections regardless of password strength... Users with Trend Micro Home Network Security are protected via the following signatures: 1133578 WEB GoAhead system.ini Information Disclosure Vulnerability -1 (CVE-2017-5674) 1133642 WEB GoAhead system.ini Information Disclosure Vulnerability -2 (CVE-2017-5674). | A new Internet of Things (IoT) botnet called Persirai (Detected by Trend Micro as ELF_PERSIRAI.A) has been discovered targeting over 1,000 Internet Protocol (IP) Camera models...
11 distinct techniques documented for this family, organized by ATT&CK tactic.
set_ftp.cgi – when the attacker knows the admin password, he can use this for command injections and malware deployment
These commands will download and execute malicious shell script from the domain ntp.gtpnet.ir. The wificam.sh will download and execute the following samples...
when it compromises an IP camera, that camera will start attacking others by exploiting three known vulnerabilities: login.cgi – allows attackers to bypass authentication and get the admin password; set_ftp.cgi – when the attacker knows the admin password, he can use this for command injections and malware deployment; CVE-2014-8361 – this vulnerability allows remote attackers to execute arbitrary code via a crafted New Internal Client request.
After the samples are downloaded and executed, the malware deletes itself and will only run in memory.
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An IoT worm/botnet referenced for similarity to Torii; it exploited UPnP weaknesses to infect IP cameras.
IP camera botnet.
IoT botnet targeting IP cameras. It propagates by exploiting vulnerabilities in custom HTTP servers and CVE-2014-8361 to bypass authentication, obtain admin passwords, execute commands, deploy malware, and spread to other cameras.
IoT botnet malware targeting vulnerable IP cameras. It gains access via exposed web interfaces and command injection, downloads and executes shell scripts and binaries, runs in memory, reports to C2 servers, propagates by exploiting an authentication bypass/information disclosure flaw in IP cameras, and performs UDP flood DDoS attacks including SSDP-based attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.